References https://askding.github.io/Kali/Exploit/Docker.html https://www.cnblogs.com/taoqinggang/articles/17863783.html https://juejin.cn/post/7022625487398633502 https://comate.baidu.com/zh/page/nzpsd0vyl7i https://github.com/vulhub/vulhub/blob/master/docker/unauthorized-rce/README.zh-cn.md https://cloud.tencent.com/developer/article/2148882 https://comate.baidu.com/zh/page/6l3ourbq5tm https://github.com/Soufaker/docker_v2_catalog https://blog.51cto.com/u_16213352/11977809 https://avd.aliyun.com/detail?id=AVD-2021-883384 https://github.com/emadshanab/goby_poc5/blob/main/Docker_Registry_API_Unauth.json https://cn-sec.com/archives/1764024.html https://blog.nsfocus.net/docker-remote-api-unauthorized-access-vulnerability/ https://tttang.com/archive/357/ https://cn-sec.com/archives/3453798.html
Related VulnerabilitiesPoCCVE-2022-39258: Mailcow Dockerized Swagger UI - Cross-Site ScriptingPoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassPoCseaweedfs-unauth: SeaweedFS Filer - Unauthenticated AccessPoCmarimo-unauth: motionEye Partial - Authentication BypassPoCCVE-2026-27771: Gitea Container Registry - Unauthorized Private Image AccessPoClaravel-nova-unauth: Laravel Nova - Unauthenticated Admin Panel AccessPoClaravel-pulse-unauth: Laravel Pulse - Unauthenticated Dashboard AccessPoCpuppetdb-dashboard-unauth: PuppetDB Dashboard - Unauthenticated AccessPoCargo-workflows-unauth: Argo Workflows - Unauthenticated DashboardPoCnode-red-unauth: Node-RED - Unauthenticated AccessPoCharbor-default-login: Harbor Registry - Default Admin CredentialsPoCdockerrun-aws-json-exposure: AWS Elastic Beanstalk Dockerrun.aws.json - ExposurePoCCVE-2024-23055: Plone Docker - Host Header Injection